pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 uses the environment of the invoking application or service during execution of the namespace.init script, which might allow local users to gain privileges by running a setuid program that relies on the pam_namespace PAM check, as demonstrated by the sudo program.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2011-01-24T17:00:00

Updated: 2018-10-10T18:57:01

Reserved: 2010-10-08T00:00:00


Link: CVE-2010-3853

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2011-01-24T18:00:02.173

Modified: 2019-01-03T15:01:45.217


Link: CVE-2010-3853

JSON object: View

cve-icon Redhat Information

No data.